SYMBOLCOMMON_NAMEaka. SYNONYMS
win.liteduke (Back to overview)

LiteDuke

Actor(s): APT29

VTCollection    

According to CarbonBlack, LiteDuke is a third stage backdoor. It appears to use the same dropper as PolyglotDuke. Its payload makes use of an AES encrypted SQLite database to store its configuration. LiteDuke supports a large number of individual commands including host information retrieval, file upload and download, and the ability to execute other code. LiteDuke C2 servers appear to be compromised servers, and the malware communicates with them using normal HTTP requests. It attempts to use a realistic User-Agent string to blend in better with normal HTTP traffic.
ESET have dubbed it LiteDuke because it uses SQLite to store information such as its configuration.

References
2020-05-18 ⋅ One Night in Norfolk ⋅ Kevin Perlow
Looking Back at LiteDuke
LiteDuke
2020-03-26 ⋅ VMWare Carbon Black ⋅ Scott Knight
The Dukes of Moscow
Cobalt Strike LiteDuke MiniDuke OnionDuke PolyglotDuke PowerDuke
Yara Rules
[TLP:WHITE] win_liteduke_auto (20260917 | Detects win.liteduke.)
rule win_liteduke_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.liteduke."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.liteduke"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { ebf4 8955fc 61 8b45fc c9 }
            // n = 5, score = 200
            //   ebf4                 | jmp                 0xfffffff6
            //   8955fc               | mov                 dword ptr [ebp - 4], edx
            //   61                   | popal               
            //   8b45fc               | mov                 eax, dword ptr [ebp - 4]
            //   c9                   | leave               

        $sequence_1 = { 83f82f 7512 66b82500 66ab 66b83200 66ab 66b84600 }
            // n = 7, score = 200
            //   83f82f               | cmp                 eax, 0x2f
            //   7512                 | jne                 0x14
            //   66b82500             | mov                 ax, 0x25
            //   66ab                 | stosw               word ptr es:[edi], ax
            //   66b83200             | mov                 ax, 0x32
            //   66ab                 | stosw               word ptr es:[edi], ax
            //   66b84600             | mov                 ax, 0x46

        $sequence_2 = { 59 8d89e0f3ffff e8???????? 5a 8d92f4f3ffff 52 }
            // n = 6, score = 200
            //   59                   | pop                 ecx
            //   8d89e0f3ffff         | lea                 ecx, [ecx - 0xc20]
            //   e8????????           |                     
            //   5a                   | pop                 edx
            //   8d92f4f3ffff         | lea                 edx, [edx - 0xc0c]
            //   52                   | push                edx

        $sequence_3 = { 8b7d08 b868000000 aa 8b450c ab b8c3000000 aa }
            // n = 7, score = 200
            //   8b7d08               | mov                 edi, dword ptr [ebp + 8]
            //   b868000000           | mov                 eax, 0x68
            //   aa                   | stosb               byte ptr es:[edi], al
            //   8b450c               | mov                 eax, dword ptr [ebp + 0xc]
            //   ab                   | stosd               dword ptr es:[edi], eax
            //   b8c3000000           | mov                 eax, 0xc3
            //   aa                   | stosb               byte ptr es:[edi], al

        $sequence_4 = { 09c0 7516 837d1000 7510 8d85fcefffff 50 ff7508 }
            // n = 7, score = 200
            //   09c0                 | or                  eax, eax
            //   7516                 | jne                 0x18
            //   837d1000             | cmp                 dword ptr [ebp + 0x10], 0
            //   7510                 | jne                 0x12
            //   8d85fcefffff         | lea                 eax, [ebp - 0x1004]
            //   50                   | push                eax
            //   ff7508               | push                dword ptr [ebp + 8]

        $sequence_5 = { 6a04 6800300000 6830010000 6a00 ff15???????? 83f800 }
            // n = 6, score = 200
            //   6a04                 | push                4
            //   6800300000           | push                0x3000
            //   6830010000           | push                0x130
            //   6a00                 | push                0
            //   ff15????????         |                     
            //   83f800               | cmp                 eax, 0

        $sequence_6 = { ad 6a04 59 c1c008 3c3d 7501 }
            // n = 6, score = 200
            //   ad                   | lodsd               eax, dword ptr [esi]
            //   6a04                 | push                4
            //   59                   | pop                 ecx
            //   c1c008               | rol                 eax, 8
            //   3c3d                 | cmp                 al, 0x3d
            //   7501                 | jne                 3

        $sequence_7 = { ff75f8 e8???????? 58 ff90d0f3ffff 61 89442438 }
            // n = 6, score = 200
            //   ff75f8               | push                dword ptr [ebp - 8]
            //   e8????????           |                     
            //   58                   | pop                 eax
            //   ff90d0f3ffff         | call                dword ptr [eax - 0xc30]
            //   61                   | popal               
            //   89442438             | mov                 dword ptr [esp + 0x38], eax

        $sequence_8 = { ff15???????? 83f800 7440 50 6a34 50 ff15???????? }
            // n = 7, score = 200
            //   ff15????????         |                     
            //   83f800               | cmp                 eax, 0
            //   7440                 | je                  0x42
            //   50                   | push                eax
            //   6a34                 | push                0x34
            //   50                   | push                eax
            //   ff15????????         |                     

        $sequence_9 = { 6a00 ff7508 e8???????? 83c408 c745f804000000 8b4508 }
            // n = 6, score = 200
            //   6a00                 | push                0
            //   ff7508               | push                dword ptr [ebp + 8]
            //   e8????????           |                     
            //   83c408               | add                 esp, 8
            //   c745f804000000       | mov                 dword ptr [ebp - 8], 4
            //   8b4508               | mov                 eax, dword ptr [ebp + 8]

    condition:
        7 of them and filesize < 1171456
}
Download all Yara Rules